
The Pentagon is free to decide that Anthropic’s restrictions make Claude the wrong AI for military use. What it cannot do, according to Judge Rita F. Lin’s August 27 ruling, is turn that contract dispute into a wider campaign that labels Anthropic a national-security supply-chain risk, orders federal agencies to cut ties, and tells military contractors they cannot conduct unrelated business with the company.
That distinction is the central point of the Pentagon Anthropic blacklist ruling. A customer can reject a vendor’s terms. An AI vendor can refuse a customer’s demands. The constitutional and statutory problem begins when the government uses powers outside the disputed transaction to punish a company for refusing those terms and publicly criticizing the government’s position.
The court’s final order permanently blocks the challenged measures while preserving the Pentagon’s ability to transition to another AI provider. In other words, Anthropic did not win a right to keep the Pentagon as a customer. It won protection against a broader set of retaliatory actions that reached far beyond whether the military bought Claude.
Key takeaways
The ruling does not give Anthropic a right to a Pentagon contract. The court explicitly preserved the government’s ability to stop using Claude and transition to another AI vendor.
The judge struck down the wider punishment. That includes the Pentagon’s supply-chain-risk designation, its order against military contractors doing commercial business with Anthropic, and several federal agencies’ actions implementing the broader blacklist.
The court found First Amendment and due-process violations. It ruled that the challenged measures constituted unlawful retaliation for protected expression and were imposed without sufficient pre-deprivation notice or an opportunity to respond.
The supply-chain statute was another problem. The law is aimed at risks such as sabotage or malicious modification of national-security systems. The court found that a vendor publicly insisting on contract restrictions did not fit that definition.
The larger fight is not completely finished. A separate D.C. Circuit case involving another procurement provision remains pending, and the government can seek appellate review of the California judgment.
What happened between Anthropic and the Pentagon
Anthropic and the Pentagon spent months negotiating over how Claude could be used by the military. The disagreement was straightforward at first. The Pentagon wanted AI contracts to permit “all lawful uses.” Anthropic was willing to remove most of its restrictions, but it maintained two: lethal autonomous warfare and mass surveillance of Americans.
The details matter because they weaken the idea that Anthropic was secretly retaining control over a deployed military system. The 59-page opinion says the two restrictions were contractual, Anthropic could not technologically enforce them after deployment, and the company lacked direct visibility into how the Pentagon used Claude. That is very different from a hidden technical mechanism that could disable, alter, or monitor a model after the government began using it.
Anthropic also publicly acknowledged the obvious consequence of refusing the Pentagon’s terms. CEO Dario Amodei said contractor selection was the Department’s prerogative and that Anthropic would support a smooth transition if the military chose another provider. That position did not ask the court to force the government to keep buying Claude. It accepted that a customer with incompatible requirements could walk away.
The dispute escalated beyond that commercial choice. On February 27 and March 3, the administration moved to designate Anthropic a supply-chain risk, direct federal agencies away from its products, and bar defense contractors from conducting commercial activity with the company. The opinion says those restrictions extended beyond military work and could reach business unrelated to the government contract at the center of the dispute.
Anthropic sued. Judge Lin initially blocked key measures. On August 27, she granted Anthropic summary judgment on most of its claims and entered permanent relief. Reuters reported the ruling in the August 28 news cycle, framing it as a major development in the company’s fight with the military over the blacklist.
That chronology is important. This did not become a major constitutional case because the Pentagon wanted different contract terms. It became one because the response to the failed negotiation reached across federal agencies and into contractors’ separate commercial relationships with Anthropic.
What Judge Lin actually struck down
The final order is unusually clear about what disappears and what remains.
First, the court declared that the challenged government actions violated the First Amendment because they were unlawful retaliation against Anthropic for constitutionally protected expression. It separately found a Fifth Amendment due-process violation because the government deprived Anthropic of protected liberty interests without sufficient advance notice or an opportunity to be heard.
Second, the court vacated the Pentagon’s supply-chain-risk designation under 10 U.S.C. § 3252. Judge Lin found the designation arbitrary and capricious, procedurally defective, and beyond the authority provided by that statute.
Third, the court struck down the portion of Hegseth’s directive stating that no military contractor, supplier, or partner could conduct commercial activity with Anthropic. The opinion described this wider mechanism as a “secondary boycott.” That phrase captures why the dispute moved beyond ordinary vendor selection. The government was no longer deciding only whether it wanted Anthropic in its own supply chain. It was attempting to influence whether other companies could maintain separate commercial relationships with Anthropic.
Finally, the court set aside actions taken by several federal agencies to implement the administration’s directive against Anthropic. Anthropic did not prevail against every defendant or on every claim. Its separation-of-powers claim, for example, failed.
That limitation should remain visible in any accurate reading of the case. This was a major Anthropic victory, but it was not a judgment that everything the government had done, or might later do, concerning the company was prohibited. The order targets specific challenged actions and specific legal defects. It also expressly preserves lawful government choices that existed before those actions.
What the Pentagon can still do with Claude
The most important part of the ruling may be what it does not require.
The Pentagon does not have to use Anthropic. It does not have to accept Claude under terms it dislikes. It does not have to structure military AI policy around Anthropic’s preferred safeguards. It can decide that its operational requirements demand a provider willing to permit all lawful uses, and it can move to another provider as long as it does so consistently with applicable law.
That means the Pentagon still has substantial power as a customer. It can decide Claude does not meet its needs. It can prefer another commercial vendor. It can conclude that relying on a proprietary model whose provider retains contractual restrictions creates an unacceptable operational dependency.
The ruling does not establish a private AI company as a veto-holder over military policy. Anthropic gets to decide the terms on which it will provide its proprietary service. The Pentagon gets to decide whether those terms are acceptable. When the two sides cannot agree, the commercial relationship can end.
That reciprocal freedom is the cleanest way to understand the case. Anthropic’s refusal did not create a legal obligation for the Pentagon to continue buying Claude. The Pentagon’s refusal to accept Anthropic’s terms did not create a legal obligation for Anthropic to abandon them.
The court objected to what happened after that point. Once the government reached beyond its own purchasing decision and used other federal powers to impose costs on Anthropic’s unrelated relationships, the dispute stopped looking like a normal procurement disagreement.
The secondary boycott was the real control lever
This case becomes much more interesting once the contract itself is separated from the government’s other powers.
Imagine an ordinary customer telling a software company, “I will not buy your product unless you remove this restriction.” The vendor refuses. The customer walks away. There is no major constitutional problem in that sequence.
Government procurement is different because the customer also controls legal and administrative machinery that can reach beyond its own purchase. It can determine eligibility for contracts, create risk classifications, influence other agencies, and impose requirements on companies that want access to federal markets.
That was the real control lever in the Anthropic case.
According to the court, the Pentagon attempted to convert a disagreement over Claude’s contract terms into a restriction affecting other commercial relationships. The February directive said that companies doing business with the military could not conduct commercial activity with Anthropic. The court found that the Pentagon lacked authority for that sweeping measure.
The mechanism matters more than the personalities involved. A government customer can have legitimate reasons to demand broad operational control over an AI system. An AI company can have legitimate reasons to refuse certain deployments. The legal question changes when the government uses powers created for one purpose to make the cost of refusal much larger than losing the disputed contract.
That distinction also explains why the case fits into the broader question of who controls AI models, speech and access. Procurement can be much more than a decision about which product a government buys. Once eligibility rules and government directives spill into unrelated business, procurement becomes leverage over a wider market.
For frontier AI companies, that leverage can shape product policy without any law directly ordering a company to change its model rules. The pressure works through access to contracts, partners, and government-controlled channels. That is why the court’s focus on the secondary boycott is more consequential than a narrow argument over whether Claude should be used for one military task.
More on AI policy:
Why the supply-chain-risk label failed
The statutory problem was almost as important as the First Amendment issue.
Under 10 U.S.C. § 3252, a supply-chain risk concerns an adversary sabotaging, maliciously modifying, or otherwise subverting a covered system so it can surveil, deny, disrupt, or degrade that system. The statute also requires a written determination that the action is necessary for national security and that less intrusive measures are not reasonably available.
The Pentagon argued that Anthropic’s insistence on contractual restrictions created an “operational veto” and raised questions about whether the government could trust the company. That concern is understandable as a procurement issue. A military customer may dislike depending on a vendor that insists on restrictions the customer considers too narrow or too difficult to manage.
Judge Lin found that this concern did not fit the statute the Pentagon used.
The opinion says the statutory language addresses covert sabotage and malicious interference rather than a supplier openly telling the government what contractual uses it will and will not accept. The court also emphasized that the government ultimately conceded Anthropic lacked backdoor access to Claude once deployed in the relevant national-security environment. It had not identified an Anthropic-specific technical vulnerability that converted an openly stated contract position into the kind of sabotage risk described by the law.
The procedural defects were important too. The record did not show the required reasoned consideration of less intrusive alternatives before the designation was imposed. That meant the problem was both substantive and procedural. The court concluded that Anthropic’s conduct did not meet the statutory definition, and it found that the government had not followed the required process for invoking the authority.
That makes the ruling more useful than a simple finding that officials were too aggressive. The decision says the government used a specific national-security tool for circumstances the court found that tool did not cover.
This point protects the distinction between a hard bargaining position and a security threat. If every vendor refusal could be translated into “supply-chain risk,” the label would become a broad procurement weapon rather than a targeted mechanism for protecting covered systems from sabotage or subversion.
Anthropic can say no, but saying no still has a price
There is an important counterweight.
Private AI companies have enormous power of their own. Claude is a hosted proprietary system. Anthropic decides which models exist, which users receive access, what contractual terms apply, and which safeguards surround different deployments. Popular AI has already examined that concentration of control in Claude Mythos shows Anthropic’s best AI is behind closed doors.
Nothing in this ruling removes that power. A future Anthropic could adopt restrictions that a government customer finds unreasonable or operationally unacceptable. The ruling does not require an agency to keep buying the product anyway.
The better rule is reciprocal: Anthropic can say no to a government use. The government can say no to Anthropic.
The cost of saying no can therefore be real. Anthropic can lose the contract. It can lose access to a particular deployment. It can watch the Pentagon move its workloads to another provider that accepts different terms. Those consequences follow naturally from the failed commercial relationship.
What the government cannot do under this judgment is automatically transform a vendor’s refusal into evidence that the vendor is a national-security threat and then use unrelated federal leverage to make that refusal commercially ruinous.
That boundary leaves both sides with meaningful control over their own choices. It does not guarantee either side the outcome it wants.
More on Anthropic:
Why the Pentagon Anthropic blacklist matters beyond one AI company
If the government could equate a difficult contractual negotiation with a supply-chain threat, the consequences would reach far beyond Claude.
Any technology contractor negotiating with the government would have to consider a second risk before objecting to a proposed term. Saying no might cost the disputed contract, which is normal. But if saying no could also threaten unrelated business with other agencies or contractors, the bargaining pressure would be far more powerful.
For a giant AI lab, that threat could mean enormous commercial consequences and disruption to major contractor relationships. For a smaller software, cybersecurity, cloud, or defense supplier, the same kind of pressure could be existential.
That possibility creates an incentive to agree first and argue later. It also changes what government procurement can do as a policy tool. Rather than merely selecting the supplier that best meets an agency’s requirements, procurement rules can become a way to influence how companies behave outside the specific contract.
The court’s reasoning pushes in the opposite direction. A government agency may choose vendors based on legitimate operational requirements, but specialized procurement powers still have statutory boundaries. Disagreement is not automatically sabotage. Criticism is not automatically a supply-chain vulnerability.
The principle also cuts both ways politically. A power broad enough to punish Anthropic for refusing one administration’s preferred AI terms would remain available to another administration with very different demands.
That is why procurement power deserves the same mechanism-focused scrutiny as licensing, account control, API access, and other AI chokepoints. Popular AI’s broader AI regulation and government power guide examines the same issue from other directions. The practical question is what happens when a company, developer, or user refuses.
More on AI regulation:
The Pentagon still had a legitimate procurement argument
None of this requires pretending the government’s underlying concern was frivolous.
The Pentagon wants military systems it can control during military operations. A private AI supplier imposing contractual restrictions on an important military tool can create an operational dependency. The government has a legitimate reason to ask whether it should tolerate that dependency.
That issue is especially sharp with a proprietary AI system. A customer may depend on the vendor for models, updates, support, deployment terms, and future capabilities. Even when the vendor cannot reach into a deployed system and flip a switch, the commercial relationship can still affect what capabilities remain available over time.
Anthropic’s own position implicitly concedes the core procurement point. It publicly said the Pentagon was entitled to pick contractors aligned with its requirements and offered to help with an orderly transition.
So the dispute did not require the Pentagon to accept Anthropic’s red lines. It required the Pentagon to make a procurement choice.
It could keep Claude under Anthropic’s terms, negotiate different terms, or use something else. Those are ordinary customer responses to a vendor whose conditions do not match the buyer’s needs.
The court found that federal officials instead added a different mechanism: use government power outside the contract to punish the company for resisting and criticizing them. That is the mechanism the judgment removes.
Keeping that distinction clear makes the article less flattering to either side and more useful. Anthropic retains substantial private control over a powerful AI system. The Pentagon retains substantial public power over military procurement. The ruling limits how one side can use public authority when a commercial disagreement becomes political.
What happens next in the Anthropic Pentagon lawsuits
The California judgment is substantial, but the legal fight around Anthropic and government procurement is not entirely over.
A separate dispute is before the U.S. Court of Appeals for the D.C. Circuit concerning another supply-chain provision, 41 U.S.C. § 4713. The D.C. Circuit’s earlier order describes a narrower Pentagon restriction focused on Department work and subcontracts while leaving contractors able to use Claude for work unrelated to the Department.
That matters because the California case and the D.C. Circuit case involve different legal mechanisms. They should not be collapsed into one simple rule about whether Anthropic is “blacklisted.” The California ruling struck down the broader challenged actions under the statutes and constitutional theories before Judge Lin. The separate appellate case concerns another procurement authority and remains its own legal track.
The government can also seek review of Judge Lin’s California judgment. That means the durable rule is not “an AI vendor can refuse the government and nothing else can happen.”
A more accurate reading is narrower and more useful: the government can impose consequences that follow from the contract, but it still needs lawful authority for consequences that reach beyond the contract.
That distinction is the durable part of the ruling even while related litigation continues. It separates vendor selection from retaliation, procurement criteria from punishment, and operational disagreement from the use of national-security classifications.
What this means for AI vendors and government contractors
For AI vendors, the lesson is to make restrictions explicit. Anthropic’s position was stated as a contract restriction, not a hidden technical control. The record’s description of its lack of a technical kill switch and lack of direct visibility into Pentagon use became important because it undercut the theory that the company itself posed the sort of sabotage risk contemplated by the statute.
That does not mean contractual restrictions are costless or automatically protected from every procurement consequence. A government customer can still reject them. The value of clarity is that it makes the actual disagreement easier to identify. The parties can argue over whether the contract works for the mission without pretending that every policy disagreement is a covert technical threat.
Government contractors have a different reason to watch the remaining D.C. litigation. Their practical concern is how far agencies can exclude Anthropic from work inside government supply chains and what restrictions apply to contractor relationships connected to Department work.
Ordinary Claude customers have another concern. The ruling is less about whether Claude works tomorrow than about who ultimately controls access to frontier AI when private platforms and governments disagree. That tension existed before the lawsuit. Popular AI’s earlier coverage of the Pentagon’s use of Claude in military operations examined how practical control can be divided among the model provider, integrator, contract, and deployment architecture rather than resting with one party.
The Anthropic case makes that control problem concrete. The company controls its proprietary model and the terms on which it offers access. The Pentagon controls its procurement choices and significant legal machinery around government contracting. Neither side is powerless. The important question is which mechanisms each side may lawfully use when their interests diverge.
More on frontier AI access controls:
The ruling draws a line between losing a contract and being punished for refusal
The Pentagon Anthropic blacklist ruling does not say AI companies get to dictate how the military operates. It does not guarantee Anthropic continued government business, and it does not force the Pentagon to accept Claude with restrictions it considers incompatible with military requirements.
It says something more defensible and more precise.
A government agency can reject a vendor whose terms it does not accept. It can buy from somebody else. It can remove the vendor from systems where the law permits it to do so. Those are consequences tied to procurement and operational choice.
What it cannot do, according to Judge Lin’s judgment, is treat the ordinary act of saying no as a license to reach for unrelated government powers. The court found constitutional violations in the retaliatory measures, statutory problems with the supply-chain designation, and legal defects in the broader contractor boycott and implementing agency actions.
Anthropic wanted the right to refuse two uses of Claude. The Pentagon had the right to refuse Anthropic in return.
The line Judge Lin drew is between losing a customer and being subjected to a broader government campaign because the vendor would not change its terms and criticized the government’s position.
For anyone watching who will control frontier AI as governments become major customers, that line may matter more than who gets the next Pentagon contract. The real precedent to watch is whether procurement remains a tool for choosing vendors, or becomes a way to discipline companies for what they refuse to build, permit, or publicly endorse.
Explore more from Popular AI:
Start here | Local AI | Builds & gear | Autonomy & policy | Fixes & guides | Popular AI podcast









Where should the line be when a government customer rejects an AI vendor’s terms? At losing the contract, or should officials have broader power to pressure the company?